Sample code for 30+ languages & platforms
PowerBuilder

SFTP Set Allowed Algorithms

See more SFTP Examples

Demonstrates how to explicitly set the algorithms allowed in the SSH connection protocol for SFTP.

Note: This example requires Chilkat v9.5.0.99 or greater.

Chilkat PowerBuilder Downloads

PowerBuilder
integer li_rc
integer li_Success
oleobject loo_Sftp
oleobject loo_Json
string ls_Allowed_kex
string ls_Allowed_hostKey
string ls_Allowed_cipher
string ls_Allowed_mac
integer li_Port

li_Success = 0

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

loo_Sftp = create oleobject
li_rc = loo_Sftp.ConnectToNewObject("Chilkat.SFtp")
if li_rc < 0 then
    destroy loo_Sftp
    MessageBox("Error","Connecting to COM object failed")
    return
end if

loo_Json = create oleobject
li_rc = loo_Json.ConnectToNewObject("Chilkat.JsonObject")

// Here are the algorithms supported by Chilkat at the time this example was written (14-June-2024)

// ---------------------------
// SSH Key-Exchange Algorithms
// ---------------------------
// curve25519-sha256
// curve25519-sha256@libssh.org
// ecdh-sha2-nistp256
// ecdh-sha2-nistp384
// ecdh-sha2-nistp521
// diffie-hellman-group14-sha256
// diffie-hellman-group16-sha512
// diffie-hellman-group18-sha512
// diffie-hellman-group-exchange-sha256
// diffie-hellman-group1-sha1
// diffie-hellman-group14-sha1
// diffie-hellman-group-exchange-sha1

// ---------------------------
// SSH Host Key Algorithms
// ---------------------------
// ssh-ed25519
// ecdsa-sha2-nistp256
// ecdsa-sha2-nistp384
// ecdsa-sha2-nistp521
// rsa-sha2-256
// rsa-sha2-512
// ssh-rsa
// ssh-dss

// ---------------------------
// SSH Cipher Algorithms
// ---------------------------
// chacha20-poly1305@openssh.com
// aes128-ctr
// aes256-ctr
// aes192-ctr
// aes128-cbc
// aes256-cbc
// aes192-cbc
// aes128-gcm@openssh.com
// aes256-gcm@openssh.com
// twofish256-cbc
// twofish128-cbc
// blowfish-cbc

// ---------------------------
// SSH MAC Algorithms
// ---------------------------
// hmac-sha2-256
// hmac-sha2-512
// hmac-sha2-256-etm@openssh.com
// hmac-sha2-512-etm@openssh.com
// hmac-sha1-etm@openssh.com
// hmac-sha1
// hmac-ripemd160
// hmac-sha1-96
// hmac-md5

// Specify the allowed key-exchange, host-key, cipher (i.e. encryption), and mac (i.e. hash) algorithms allowed, in the order of preference.
// -------------------------------------------------------------------------------------------------------------------------------------------
// Note: You typically should NOT explicitly set allowed algorithms.
// By default, Chilkat orders algorithms according to best practices, and pays attention to vulnerabilities such as the "Terrapin Attack".
// Hard-coding algorthims can make your application brittle and prone to breaking over a long period of time,
// if a server (at some point in the future) changes its allowed algorithms, or if you connect to a different server,
// such that the client (Chilkat) and server cannot find a set of mutually agreed-upon algorithms.
// -------------------------------------------------------------------------------------------------------------------------------------------
ls_Allowed_kex = "curve25519-sha256@libssh.org,ecdh-sha2-nistp256"
ls_Allowed_hostKey = "ssh-ed25519,ecdsa-sha2-nistp256"
ls_Allowed_cipher = "chacha20-poly1305@openssh.com,aes256-ctr"
ls_Allowed_mac = "hmac-sha2-256,hmac-sha2-512"

loo_Json.UpdateString("kex",ls_Allowed_kex)
loo_Json.UpdateString("hostKey",ls_Allowed_hostKey)
loo_Json.UpdateString("cipher",ls_Allowed_cipher)
loo_Json.UpdateString("mac",ls_Allowed_mac)
loo_Sftp.SetAllowedAlgorithms(loo_Json)

li_Port = 22
li_Success = loo_Sftp.Connect("example.com",li_Port)
if li_Success <> 1 then
    Write-Debug loo_Sftp.LastErrorText
    destroy loo_Sftp
    destroy loo_Json
    return
end if

Write-Debug "Connected."

// ....
// ....


destroy loo_Sftp
destroy loo_Json